# Please validate mutiple GROK filter

**URL:** <https://discuss.elastic.co/t/please-validate-mutiple-grok-filter/127738>\
**Category:** Logstash\
**Created:** [April 12, 2018, 6:12am UTC](https://discuss.elastic.co/t/please-validate-mutiple-grok-filter/127738 "2018-04-12T06:12:51Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 12, 2018, 6:24am UTC](https://discuss.elastic.co/t/please-validate-mutiple-grok-filter/127738/2 "2018-04-12T06:24:02Z")

</div>

Please don't start new threads that continue the same question ([How to use multiple filters and multiple Grok filters](https://discuss.elastic.co/t/how-to-use-multiple-filters-and-multiple-grok-filters/127723)).

What you have works but most of your messages will get tagged `_grokparsefailure` since all grok filters are run on each message and there's probably at least one that doesn't match the message. It's also very inefficient. Instead, list multiple expressions in a single grok filter. There's an example of this in the grok filter documentation.

---

_[View the full topic](https://discuss.elastic.co/t/please-validate-mutiple-grok-filter/127738)._
